Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
Google reports attackers used AI agents to steal credentials in under six hours
00

Google reports attackers used AI agents to steal credentials in under six hours

Sep 8, 2026

Google Threat Intelligence Group reports that a financially motivated threat actor used an autonomous, multi-agent AI framework to compromise thousands of credentials in under six hours. By combining an AI chatbot, custom prompts, and preconfigured playbooks, the system managed vulnerability scanning, troubleshooting, and IP rotation entirely without human intervention. This shift toward agentic AI significantly accelerates attack speeds, shrinking the window defenders have to react.

AI-powered credential harvesting attack

  • ▪The threat actor used an AI coding chatbot, a prompt, and preconfigured markdown instruction sets as playbooks to automate scanning, troubleshooting, and IP rotation during the six-hour credential harvesting campaign
  • ▪The network traffic from the six-hour credential harvesting campaign originated from the victim organization's own IP addresses, making the malicious activity appear legitimate
  • ▪A financially motivated threat actor compromised an unnamed organization's cloud infrastructure to deploy an autonomous, multi-agent attack framework that harvested thousands of credentials in under six hours

Autonomous multi-agent attack frameworks

  • ▪A China-aligned cyber espionage group used Gemini to design an automated penetration testing framework intended to autonomously perform port scanning and service parsing in unpredictable environments
  • ▪Google Threat Intelligence Group disabled the assets associated with the China-aligned group's automated penetration testing framework before the group could deploy it in the wild

TeamPCP supply chain compromises

  • ▪TeamPCP deployed credential stealers named SANDCLOCK and DUSTMAKER to target AI coding assistants and cloud credentials, which were then monetized through direct sales or ransomware partnerships
  • ▪TeamPCP used prompt injections containing extreme requests about biological and nuclear weapons to force large language model security scanners to refuse and skip scanning malicious JavaScript files
  • ▪The financially motivated threat actor TeamPCP, also known as Altered Spider and UNC6780, conducted large-scale software supply chain compromises targeting PyPI, npm, and Docker Hub
  • ▪TeamPCP's DUSTMAKER credential stealer drops malicious files into hidden project directories like .claude and .cursor to evade detection by appearing as ordinary developer clutter

Proprietary AI model theft

  • ▪The China-nexus threat actor UNC6508 compromised cloud environments to host local, open-weight LLM infrastructure, allowing them to evade commercial API monitoring
  • ▪Threat actors targeted proprietary AI assets across healthcare, government, and media sectors to exfiltrate API credentials, models, skills, prompts, source code, and related research
  • ▪A healthcare company lost drug research and a proprietary AI model to extortionists who threatened to publish the stolen data unless they received payment

Threat actor AI adoption

  • ▪The China-nexus cyber espionage groups Basin Castle and Ravine Castle have used large language models like Claude, Gemini, or Codex to write exploit scripts, generate spear-phishing lures, and troubleshoot errors
  • ▪John Hultquist of Google Threat Intelligence Group stated that security defenders must assume all threat actors are currently using AI in some capacity to benefit their operations
  • ▪The Russian cyber espionage group Sandworm and the Iranian hacking group Calanque Ion have integrated Gemini and other generative AI models to support intelligence gathering, social engineering, and workflow automation

2 sources

SiliconANGLE
Google says attackers used AI agents to steal credentials in under six hours - SiliconANGLE
View source article
The Hacker News
Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours
View source article

Featured stories

Alphabet receives $115 billion in orders for $25 billion bond offering

Aug 6, 2026 · 2 sources

Google Unveils 8th-Generation TPUs and Enterprise AI Agent Platform at Cloud Next 2026

Apr 23, 2026 · 12 sources

Google launches Nano Banana 2 Lite and Gemini Omni Flash AI models for fast, low-cost media generation

Jun 30, 2026 · 9 sources

Story comments

Loading comments…

Related Projects

Google

Topics

CybersecurityAI agentsAI security

Featured stories

Alphabet receives $115 billion in orders for $25 billion bond offering

Aug 6, 2026 · 2 sources

Google Unveils 8th-Generation TPUs and Enterprise AI Agent Platform at Cloud Next 2026

Apr 23, 2026 · 12 sources

Google launches Nano Banana 2 Lite and Gemini Omni Flash AI models for fast, low-cost media generation

Jun 30, 2026 · 9 sources